Legal
Privacy
Last updated: July 31, 2026
This policy describes how sndwrks Inc., a New York corporation ("sndwrks", "we", "us"), collects, uses, and shares information when you use our websites, products, and services, including the sndwrks cloud service at app.sndwrks.com. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), sndwrks Inc. is the data controller for our websites and for account and billing information on the sndwrks cloud service. Where the service processes system telemetry and other content on behalf of a business customer, we process that data to provide the service to that customer. For any questions, or to exercise your rights, contact us at info@sndwrks.xyz or by mail at sndwrks Inc., 14-41 Broadway 7D, Astoria, NY 11106, United States.
What we collect — website
We collect information you provide directly to us — for example, when you purchase a license or contact support through our contact form. We also collect limited technical information needed to deliver and secure the site (such as server logs). Our contact form is protected by Cloudflare Turnstile to filter automated abuse, our payments are processed by Stripe, our fonts are served by Adobe, and we use Umami for privacy-focused, cookieless website analytics. We do not use advertising or tracking cookies, and we do not track you across other sites.
What we collect — sndwrks cloud
If your organization uses the sndwrks cloud service, we collect and store: your account profile (name, email address, timezone, locale, and country — we use your country only to decide whether we may offer you optional analytics); login records, including IP address and approximate location; your organization's billing details (addresses and tax IDs); payment method details limited to card brand, last four digits, and expiry — full card and bank numbers are collected directly by Stripe and are not stored by us; system and device telemetry, events, and backups that your organization's equipment sends to the service; feedback you choose to submit; the notifications we send you; and your notification preferences. Your sign-in credentials and any phone number used for multi-factor authentication are held by our sign-in provider, Stytch — we do not store passwords or MFA phone numbers.
AI assistant
Some sndwrks systems include an AI assistant feature. Assistant requests pass through our servers to Anthropic for processing. Our systems are designed not to store or log the content of assistant conversations; we retain only usage metadata such as token counts, timing, and request status.
Cookies and local storage
On our website we use only strictly necessary cookies and local storage required for the site to function (for example, to remember that you have dismissed a notice), and our Umami website analytics is cookieless. We do not set advertising, analytics, or tracking cookies on the website, so no consent is required for the cookies we use. We do not respond to browser "Do Not Track" signals; as described in this policy, we do not track you across other sites. On the sndwrks cloud portal we set strictly necessary session cookies to keep you signed in; if you opt in to product analytics, PostHog stores its identifier in your browser's local storage rather than in a cookie; and Stripe's payment component loads on the billing page to collect payment details securely. Our fonts are served by Adobe Typekit; Adobe's own privacy policy applies to that service.
Product analytics
On the sndwrks cloud portal we offer optional product analytics, powered by PostHog and hosted in the United States. Analytics is off by default and runs only if you opt in. We offer this choice only to users whose account country is on a limited list (currently the United States, Canada, Australia, New Zealand, and Japan); for accounts in other countries — including everyone in the EEA and the UK — analytics is never offered and no analytics data is collected. If you opt in, analytics may include page views with identifying details stripped from web addresses, a small set of product-usage events, an internal user identifier, and recordings of how you interact with the portal (session replay). You can opt out at any time in Settings → Privacy, with immediate effect.
How we use your information
We use the information we collect to operate, maintain, secure, and improve our products and the sndwrks cloud service; to bill for subscriptions and purchases and calculate applicable taxes; to send service notifications; to respond to support requests; and to comply with legal obligations. Operational alert emails are opt-in and off by default. Required billing and account notices — invoices, payment receipts, payment-failure notices, and subscription-ending notices — are sent to the users your organization designates as billing users or customer administrators and cannot be disabled while the account has billing activity. Product-improvement analytics runs only with your consent, as described above.
Lawful bases for processing
Where the GDPR applies, we rely on the following lawful bases: performance of a contract (to fulfil orders, provide the sndwrks cloud service, and bill for subscriptions); our legitimate interests (to operate, secure, and improve our services, prevent fraud and abuse, and keep login audit records); compliance with legal obligations (such as tax and accounting requirements); and your consent, where we ask for it (such as optional product analytics). You may withdraw consent at any time without affecting processing carried out beforehand.
Who we share information with
We share information with service providers who process it on our behalf: Amazon Web Services (hosting, in the United States); Stytch (sign-in and authentication); Stripe (payment processing and tax calculation); Postmark (email delivery); Anthropic (AI assistant processing); PostHog (optional product analytics, in the United States); Grafana Cloud (operational logs and metrics, which are engineered to exclude personal data); Umami (cloud-hosted, cookieless website analytics); Tailscale (encrypted network tunnels that carry data between customer equipment and our servers); Adobe (font delivery); and Cloudflare (bot protection on our website contact form). We also share information as required by law. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
International data transfers
sndwrks is based in the United States, and the sndwrks cloud service is hosted in the United States (Amazon Web Services, US East). When we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (and the UK Addendum) — to protect that data.
Data retention
We keep personal information only for as long as necessary for the purposes described in this policy. In particular: account information is kept for the life of the account and for a reasonable period afterwards; login records and operational logs are kept for a limited security-audit window; invoices and billing records are kept for as long as needed for tax, accounting, and audit purposes; feedback comments are deleted after 180 days; AI assistant interaction traces are deleted after 90 days, while aggregate token-usage accounting is retained for billing and abuse-prevention purposes; system backups are kept on a rotation schedule; and if you withdraw analytics consent we stop collecting analytics data immediately and delete or de-identify previously collected analytics data within a reasonable period.
Your rights under the GDPR
If you are in the EEA or the UK, you have the right to access your personal data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing; to data portability; and to withdraw consent where we rely on it. To exercise any of these rights, email info@sndwrks.xyz. We respond within one month, extendable where the law permits for complex requests. Where we process data on behalf of a business customer (for example, system telemetry), we may refer your request to that customer. You also have the right to lodge a complaint with your local data protection supervisory authority.
California and other US state privacy rights
To the extent the California Consumer Privacy Act, as amended ("CCPA"), or a similar US state privacy law applies to us — we believe we currently fall below the CCPA's applicability thresholds — this section applies to residents of those states. In the last twelve months we have collected the following categories of personal information: identifiers (such as name, email address, and IP address); commercial information (such as purchase and subscription records); internet or other electronic network activity information (such as login records and, with your consent, product analytics); geolocation data (location information derived from login records and business addresses); and professional or employment-related information (such as your role at the organization that holds your account). We collect these categories for the business purposes described in "How we use your information", and we retain them according to the criteria in "Data retention". We do not sell personal information and we do not share it for cross-context behavioral advertising, so we do not offer an opt-out of sale or sharing. You have the right to know and access the personal information we hold about you, to request deletion, to request correction, and not to be discriminated against for exercising these rights. You may exercise these rights by emailing info@sndwrks.xyz or calling +1 (201) 701-3155, and you may use an authorized agent to submit a request on your behalf. Most personal information we hold relates to individuals acting for a business customer, and we honor these rights to the extent the law provides them in that context.
Children
Our websites and services are not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Security
We protect personal information with encryption in transit, access controls, and network isolation, and we delegate credential and payment-detail storage to specialized providers — passwords and MFA phone numbers are held by Stytch, and card and bank numbers by Stripe. No card or bank account numbers are stored on our systems.
Changes to this policy
We may update this policy from time to time. We will post updates on this page with a new "Last updated" date and, for material changes, notify account holders by email.